Files
unraid-podman/versions.env
T
maggesandClaude Sonnet 5 e2fefcdf9c
Build Packages / Build .txz packages (push) Failing after 9s
Lint / ShellCheck (push) Failing after 43s
Lint / Validate .plg XML (push) Successful in 10s
Lint / EditorConfig (push) Failing after 6s
Add reproducible build system, native Unraid plugin, and WebUI
- versions.env pins podman, conmon, crun, netavark, aardvark-dns, passt,
  and fuse-overlayfs to verified upstream source checksums; SlackBuild
  recipes, scripts/build-packages.sh, checksums.sh, release.sh, and
  update-versions.sh implement the reproducible pipeline; GitHub Actions
  workflows build in a Slackware container and publish releases without
  committing any binaries.

- plugin/podman.plg installs/updates/removes all eight packages (the
  seven components plus the plugin's own unraid-podman scaffolding
  package) via upgradepkg, using the official Unraid array-event hook
  mechanism (event/disks_mounted, event/stopping) instead of editing
  /boot/config/go. rc.podman and the sbin/ helper scripts implement
  storage creation, config seeding/sync, preflight checks, autostart
  with per-container Safe-Mode, and package verify/update/rollback.

- webui/plugins/podman implements the Dashboard, Containers, Pods,
  Images, Volumes, Networks, Logs, Terminal, Compose, and Settings
  panels against the approved mockup (webui/mockups/prototype.html),
  talking to podman system service exclusively via PodmanClient.php
  (libpod REST API over the Unix socket), with two documented
  exceptions: Terminal's one-shot exec model and Compose's use of the
  podman compose CLI, since libpod has no REST equivalent for either.

- docs/ARCHITECTURE.md and docs/ROADMAP.md record the design decisions
  and honest current status (syntax-checked, unit- and
  integration-tested against fake sockets/servers; not yet run against
  a real Unraid/Podman/Slackware system).

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-11 10:51:14 +00:00

87 lines
4.8 KiB
Bash

# =============================================================================
# versions.env — single source of truth for upstream component versions.
#
# Every SlackBuild under packages/*/ and the orchestrator
# (scripts/build-packages.sh) source this file instead of hardcoding a
# version or URL. This is what makes the build reproducible: given the same
# versions.env, the same source tarballs (verified by SHA256) are fetched and
# built, every time.
#
# To bump a component's version, run scripts/update-versions.sh <component>
# (fetches the new upstream release, recomputes the checksum, rewrites the
# corresponding block below) rather than editing hashes by hand.
#
# SHA256 sums below were computed directly against the upstream source
# tarball/snapshot at the time of pinning (see the fetch command in each
# comment). GitHub's auto-generated "archive/refs/tags" tarballs are stable
# in practice but are NOT cryptographically signed by upstream — treat this
# checksum as tamper-evidence against a compromised mirror/CDN, not as a
# replacement for verifying upstream's own release signing where available.
# =============================================================================
# --- podman ------------------------------------------------------------------
# https://github.com/containers/podman
PODMAN_VERSION="6.0.1"
PODMAN_SRC_URL="https://github.com/containers/podman/archive/refs/tags/v${PODMAN_VERSION}.tar.gz"
PODMAN_SRC_SHA256="4829d7c1423523a6a4d5537dea7968ae7f6c22ed7f1d5f416638fd81c83caa47"
# --- conmon --------------------------------------------------------------
# https://github.com/containers/conmon
CONMON_VERSION="2.2.1"
CONMON_SRC_URL="https://github.com/containers/conmon/archive/refs/tags/v${CONMON_VERSION}.tar.gz"
CONMON_SRC_SHA256="814fb5979a3a4b8576b1f901e606b482bebb41cb7e57926e6d5765ee786b96d3"
# --- crun ----------------------------------------------------------------
# https://github.com/containers/crun
CRUN_VERSION="1.28"
CRUN_SRC_URL="https://github.com/containers/crun/archive/refs/tags/${CRUN_VERSION}.tar.gz"
CRUN_SRC_SHA256="90284c7f097f8ee72a6447978c263e1b1355727c2f2ca0ac667e6d57788f46f5"
# --- netavark --------------------------------------------------------------
# https://github.com/containers/netavark
NETAVARK_VERSION="2.0.0"
NETAVARK_SRC_URL="https://github.com/containers/netavark/archive/refs/tags/v${NETAVARK_VERSION}.tar.gz"
NETAVARK_SRC_SHA256="031aeeacc930382e8635d40a885798eff1da164dfcf9024b698f822e5995d9c8"
# --- aardvark-dns ----------------------------------------------------------
# https://github.com/containers/aardvark-dns
AARDVARK_DNS_VERSION="2.0.0"
AARDVARK_DNS_SRC_URL="https://github.com/containers/aardvark-dns/archive/refs/tags/v${AARDVARK_DNS_VERSION}.tar.gz"
AARDVARK_DNS_SRC_SHA256="d3f5d6b3be3c2d80e8257fb9467e34ff104f299474427979454034dca6dc88cc"
# --- fuse-overlayfs --------------------------------------------------------
# https://github.com/containers/fuse-overlayfs
FUSE_OVERLAYFS_VERSION="1.17"
FUSE_OVERLAYFS_SRC_URL="https://github.com/containers/fuse-overlayfs/archive/refs/tags/v${FUSE_OVERLAYFS_VERSION}.tar.gz"
FUSE_OVERLAYFS_SRC_SHA256="cefffecfbb001b2784f19af344f27eae07b31a4faa38d345b738af96b2bec59e"
# --- passt -------------------------------------------------------------------
# https://passt.top/passt/about/ — "Plug A Simple Socket Transport". Podman's
# modern (post-slirp4netns) rootless network transport. Upstream has NO
# GitHub mirror and no semver tags; it is released continuously from the
# cgit-hosted git repository at https://passt.top/passt/, identified by full
# git commit hash. We pin to a specific commit snapshot for reproducibility,
# fetched via cgit's snapshot endpoint:
# https://passt.top/passt/snapshot/passt-<commit>.tar.gz
PASST_COMMIT="6ef3d1c86ffc690a17a9a4445df4a741446bcd44"
PASST_VERSION="git${PASST_COMMIT:0:7}"
PASST_SRC_URL="https://passt.top/passt/snapshot/passt-${PASST_COMMIT}.tar.gz"
PASST_SRC_SHA256="4c58a77504a77d613464dddf22ae69d749a5ba64cb87e44c3b8c252333e209fc"
# =============================================================================
# Slackware package BUILD number (not upstream version). Bump this if a
# package must be rebuilt without an upstream version change (e.g. a
# packaging-only fix). Reset to 1 whenever *_VERSION above changes.
# =============================================================================
PKG_BUILD="1"
# Slackware package architecture. Unraid is x86_64-only today; kept as a
# variable rather than hardcoded so the build scripts don't need a second
# source of truth if that ever changes.
PKG_ARCH="x86_64"
# Suffix appended to every package's tag field (Slackware convention:
# <name>-<version>-<arch>-<build><tag>.txz), identifies packages built by
# this project as opposed to a stock Slackware/SBo package of the same name.
PKG_TAG="_unraidpodman"